EP1593015A1

Architecture for encrypted application installation

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 3 February 2023, 3.6 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

14 claims: 6 independent, 8 dependent

  1. 1
    Claims of equivalent WO 2004070587 A1 CLAIMS 1. A method for providing an application to be executed on a device, the device being arranged with a secure environment to which access is strictly controlled by a device processor, the method comprising:providing the device (201) with an encrypted application (204) ;providing, via a secure channel (207) into the secure environment (205) , the device (201) with a first key for decrypting said encrypted application (204) ;decrypting, in the secure environment (205) , said encrypted application (204) by means of said first key;re-encrypting, in said secure environment, the application (209) by means of a second key;and storing, outside said secure environment, the re- encrypted application.
  2. 2
    A method for providing an application to be executed on a device, the device being arranged with a secure environment to which access is strictly controlled by a device processor, the method comprising:providing the device (201) with an encrypted application (204) ;providing, via a secure channel (207) into the secure environment (205) , the device (201) with a first key for decrypting said encrypted application (204) ;encrypting, in said secure environment (205) , said first key by means of a second, key;and storing, outside said secure environment (205) , the encrypted first key.
  3. 7
    The method according to any of the previous claims, wherein multiple keys can be transferred successively on the secure channel into the secure environment, each key being used to decrypt a corresponding encrypted application in the secure environment .
  4. 8
    A system arranged to provide an application to be executed on a device, the device being arranged with a secure environment to which access is controlled by a device processor, the system comprising:means for providing the device (201) with an encrypted application (204) ;means for providing, via a secure channel (207) into the secure environment (205) , the device (201) with a first key for decrypting said encrypted application (204) ;means for decrypting, in the secure environment (205) , said encrypted application (204) by means of said first key;means for re-encrypting, in said secure environment, the application (209) by means of a second key;and means for storing, outside said secure environment, the re-encrypted application.
  5. 9
    A system arranged to provide an application to be executed on a device, the device being arranged with a secure environment to which access is controlled by a device processor, the system comprising:means for providing the device (201) with an encrypted application (204) ;means for providing, via a secure channel (207) into the secure environment (205) , the device (201) with a first key for decrypting said encrypted application (204) ;means for encrypting, in said secure environment (205) , said first key by means of a second key;and means for storing, outside said secure environment (205) , the encrypted first key.
  6. 14
    The system according to any of the claims 8-13, wherein the system is arranged such that multiple keys can be transferred successively on the secure channel into the secure environment, each key being used to decrypt a corresponding encrypted application in the secure environment .